Controlled Unclassified Information is often present in organizations that don't realize it. Here's how to identify it and understand what that means for your security obligations.
Controlled Unclassified Information (CUI) is a federal designation for information that requires safeguarding under law, regulation, or government-wide policy — but is not classified. The challenge for most companies is that CUI can enter an organization without anyone explicitly labeling it, and the security obligations that come with it apply regardless of whether you knew the data was CUI.
If your organization works with the federal government or its contractors, there is a reasonable chance you handle CUI. The consequences of not knowing — and not protecting it — include contract loss, False Claims Act liability, and disqualification from future DoD work.
Here is how to determine whether CUI applies to your organization — and what to do if it does.
CUI is defined by the National Archives and Records Administration (NARA) CUI Registry, which lists over 100 specific categories of information that qualify. The categories span defense, financial, legal, health, research, and critical infrastructure domains.
CUI is not the same as classified information. It does not require a security clearance to handle. But it does require specific safeguarding measures — and those measures are defined by NIST SP 800-171, which is the foundation of CMMC compliance.
Common CUI categories relevant to defense contractors and their supply chains include:
Defense and procurement
Financial and legal
Health and safety
Research and intellectual property
You do not need to see the letters "CUI" on a document to be handling it. If any of the following apply, your organization likely has CUI obligations:
Not all sensitive information is CUI. The designation is specific to federal law, regulation, or government-wide policy. The following are generally not CUI:
Review your contracts
Look for DFARS clauses, references to NIST SP 800-171, or language about "covered defense information," "controlled technical information," or "controlled unclassified information." If you find them, CUI obligations apply.
Identify where the data flows
Map where CUI enters your organization, where it is stored, who accesses it, and how it leaves. This becomes your system boundary — the scope of your CMMC or NIST 800-171 assessment.
Assess your current controls
NIST SP 800-171 has 110 security requirements across 14 control families. A gap assessment against these requirements tells you where you stand and what you need to fix before a formal assessment.
Understand your CMMC level
If your contract involves CUI, you likely need CMMC Level 2 compliance — which requires a third-party assessment (C3PAO) for most contracts. Understanding your level determines your timeline and investment.
Download the CMMC & NIST 800-171 Readiness Checklist to assess where your organization stands against the 110 NIST 800-171 requirements.
CMMC enforcement is accelerating. DoD contracts now require contractors to self-attest or obtain third-party certification depending on the CUI sensitivity level. Organizations that discover they handle CUI after a contract award — or after an incident — face compressed timelines, potential contract loss, and in some cases False Claims Act liability for misrepresenting their compliance posture.
The first step is simply knowing. A contract review and a brief scoping conversation with a qualified advisor can answer the question definitively — and give you a clear picture of what NIST 800-171 compliance looks like for your organization.
Classified information requires a security clearance to access and is marked with classification levels (Confidential, Secret, Top Secret). CUI does not require a clearance but does require specific safeguarding measures under federal law or regulation. Many defense contractors handle CUI without ever handling classified information.
No. CUI obligations apply based on the nature of the information, not whether it has been labeled. If your organization receives technical drawings, specifications, or other data from a defense contractor under a federal contract, that data may be CUI regardless of whether it is marked as such.
Organizations that handle CUI under DoD contracts are required to implement the 110 security requirements in NIST SP 800-171. CMMC Level 2 formalizes these requirements and adds third-party assessment obligations for most contracts involving CUI.
Non-compliance with CUI safeguarding requirements can result in contract termination, disqualification from future DoD work, and in cases where compliance was misrepresented, False Claims Act liability. The risk increases as CMMC enforcement accelerates.
Review your contracts and subcontracts for DFARS clause 252.204-7012 (Safeguarding Covered Defense Information), references to NIST SP 800-171, or language about CUI or controlled technical information. If you are a subcontractor, ask your prime contractor directly.